On June 16, 2026, Governor Phil Scott signed Act No. 145 (S.71) into law, creating the Vermont Data Privacy and Online Surveillance Act (VDPOSA). The VDPOSA takes effect on January 1, 2028 and will be codified at 9 V.S.A. §§ 2415a–2415k. The VDPOSA resembles many of the comprehensive state privacy laws already enacted across the United States—19 are currently in effect, with four more, including Vermont’s, arriving in 2027 or 2028—although it departs from the pack in various respects.
The VDPOSA protects the personal data of a “consumer,” defined as a Vermont resident acting in an individual or household capacity, not a commercial or employment one. “Personal data” is any information linked or reasonably linkable to an identifiable individual or to a device (a device-inclusive scope is wider than many peer laws) and excludes deidentified data and publicly-available information. “Sensitive data” is personal data that is or reveals racial/ethnic origin, religious beliefs, sex life and sexual orientation, transgender/nonbinary status, citizenship or immigration status, health information, neural data, precise geolocation data, biometric and genetic data, children’s data, financial account information, and government-issued ID numbers. A “controller” determines the purpose and means of processing personal data, while a “processor” processes data on a controller’s behalf. Controllers handling consumer health data are separately designated as “consumer health data controllers.” “Processing” is defined broadly to cover any operations performed on personal data, such as collection, use, storage, disclosure, analysis, deletion, or modification.
The VDPOSA applies to any person that conducts business in Vermont or targets Vermont residents and, in the preceding year, controlled or processed the personal data of 35,000 or more consumers or the sensitive data of 3,000 or more consumers, sold the personal data of 3,000 or more consumers, or controlled or processed consumer health data. These comparatively low thresholds mean the law will likely apply widely, both inside and outside the state, although it bears noting personal data controlled or processed solely for the purpose of completing a payment transaction does not count toward the thresholds. As with other states’ laws, the VDPOSA identifies extensive entity-, data-, and activity-level exemptions from its scope. But notably, unlike many states, Vermont provides no across-the-board exemptions for nonprofit organizations or institutions of higher education.
Consumers receive a familiar bundle of rights concerning their personal data: to confirm processing, access their data, correct inaccuracies, delete their data, obtain a portable copy, and opt out of targeted advertising, sale, or profiling that produces legal or similarly significant effects. Consumers may also question the outcome of certain profiling and obtain a list of third parties to which their data was sold. Controllers must respond to consumers’ rights requests within 45 days, honor authenticated requests, and maintain an appeal process resolving appeals within 60 days.
The VDPOSA places substantial affirmative duties on controllers. They must minimize data collection to what is reasonably necessary, maintain reasonable security practices, provide an effective means to revoke consent and cease processing within 15 days of revocation, and publish a clear privacy notice. Controllers may not process data for incompatible new purposes without consent, process or sell sensitive data without consent and a reasonable basis, process or sell sensitive data of children unless in accordance with other applicable laws, sell or process for targeted advertising the data of consumers known to be ages 13 to 17, or discriminate against consumers who exercise their rights under the statute. Processors must follow controller instructions, assist with compliance obligations, provide privacy assessment reports to controllers upon request, and operate under written contracts. Data processing contracts must specify processing instructions; identify the types of data processed, as well as the nature, purpose, and duration of the processing; impose confidentiality duties; and address deletion, compliance auditing, and subcontracting.
The privacy notice required by the VDPOSA must be conspicuous and accessible, and must describe the categories of data processed, the means and purposes of processing, categories of data sold and the third parties receiving it, processing or sale of personal data for targeted advertising, and consumers’ rights along with procedures for exercising and appealing them. Notably, the privacy notice must also disclose whether the controller uses personal data to train large language models. Any “retroactive material change” to a controller’s privacy notice or practices requires notice to affected consumers and an opportunity to withdraw consent.
Controllers must conduct data protection assessments, weighing benefits against risk, for higher-risk activities—targeted advertising, sale, certain profiling, and processing of sensitive data—and must prepare impact assessments for profiling that drives significant decisions. The Vermont Attorney General may compel disclosure of these assessments, which remain confidential and exempt from public records requests.
The VDPOSA also addresses deidentified and pseudonymous data, imposing anti-reidentification safeguards. It also includes dedicated consumer health data protections, including confidentiality requirements, a bar on selling health data without consent, and certain restrictions on use of a geofence to establish a virtual boundary that is within 1,850 feet of a health care facility.
Enforcement rests exclusively with the Vermont Attorney General, with violations treated as violations of the Vermont Consumer Protection Act. There is no private right of action. Through June 30, 2029, the Attorney General must offer a 60-day cure period before pursuing enforcement where a cure is possible.
How can your business prepare to comply with the VDPOSA? Here are some important steps:
- Determine what types of personal data regarding Vermont residents your business processes in a given year, and for how many Vermont residents your business processes the data (remember: “personal data” and “processing” are broadly defined);
- Understand how and where you collect or receive data—which might not be obvious at first glance;
- Determine the purposes for which your business processes personal data of Vermont residents and whether this processing is necessary and is limited as much as reasonably possible;
- Identify third parties with whom your business shares personal data, how it is shared, for what purposes it is shared, and whether there is an adequate contract in place to govern the data;
- Assess whether your business’s current privacy policy/notice (if you have one) adequately describes and discloses the organization’s data practices; and
- Establish secure and reliable mechanisms for consumers to exercise their rights under the VDPOSA, and also to manage consent choices.
Disclaimer: This article provides general information about data privacy and is not a substitute for professional legal advice. Privacy requirements may vary by organization, jurisdiction, and industry. Always consult with a qualified data privacy attorney to develop strategies tailored to your specific needs.